CVE Vulnerabilities

CVE-2015-0259

Insufficient Verification of Data Authenticity

Published: Apr 01, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
4.9 IMPORTANT
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for access to consoles via a crafted webpage.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

NameVendorStart VersionEnd Version
NovaOpenstack2014.1 (including)2014.1.4 (excluding)
NovaOpenstack2014.2 (including)2014.2.3 (excluding)
NovaOpenstack2015.1.0-milestone1 (including)2015.1.0-milestone1 (including)
NovaOpenstack2015.1.0-milestone2 (including)2015.1.0-milestone2 (including)
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6RedHatopenstack-nova-0:2014.1.4-3.el6ost*
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7RedHatopenstack-nova-0:2014.1.4-3.el7ost*
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7RedHatopenstack-nova-0:2014.2.2-19.el7ost*
NovaUbuntuupstream*

References